Forced Reboot due to System Errors (Vista)

Discussion in 'Malware Help (A Specialist Will Reply)' started by rove02, Aug 23, 2010.

  1. rove02

    rove02 Private E-2

    Hi, I went through all of the Read and Run Me thread and pretty sure I did it all correctly. My problem probably started 2-3 days ago when I was about to link my wireless printer at school to my computer. I got two error messages that popped up:

    1. Services and Controller app has stopped working

    2. Windows has encountered a critical problem and will shutdown in 1 minute

    After the computer restarted the same errors appeared and it shutdown again. At this point I decided to try and boot into Safe Mode with Networking to try and research the problem online. When the computer booted into Safe Mode with Networking the same error messages popped up and the computer was again forced to reboot.

    I later discovered that connecting to the internet was what was causing the errors and am now able to boot into Normal Mode as long as I disable the WiFi.

    A few days prior to all this I got a virus pretending to be an Anti-virus program; I think it was Security Suite. I have had these fake programs before and was able to get rid of them in the past so I just ran Malwarebytes and Spybot in Safe Mode and thought it had done the job as my computer was fine for a couple days.
     

    Attached Files:

    Last edited: Aug 23, 2010
  2. rove02

    rove02 Private E-2

    Other log:
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you did not deliberately set this proxy yourself then please include it in the HJT fix below:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Windows\System32\drivers\jvhdaxu.sys
    c:\users\Trevor\AppData\Local\Akobokidup.dat
    c:\users\Trevor\AppData\Local\Awusuz.bin
    
    DirLook::
    c:\programdata\Update
    c:\users\Trevor\AppData\Roaming\57EF3AB3C7929F3CD297A82E9A680FD6
    
    Folder::
    c:\users\Trevor\AppData\Roaming\dxnlelotr
    c:\users\Trevor\AppData\Local\dxnlelotr
    c:\users\Trevor\AppData\Local\jkclekbsc
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\jvhdaxu]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know how things are running!
     
  5. rove02

    rove02 Private E-2

    After running combofix it said it was rebooting the system and not to manually. After it rebooted it prepared the log and when I went to try to finish the rest of your instructions and run getlogs.bat I got an error saying

    Illegal operation attempted on a registry key that has been marked for deletion.

    It gives this error when trying to open anything else also.
     
  6. rove02

    rove02 Private E-2

    Sorry for the extra post here is the combofix log.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, this is quite common, usually I find a reboot puts everything right again, so do that and then run the getlogs.bat to create a new C:\Mglogs.zip. Attach that.
     
  8. rove02

    rove02 Private E-2

    Well I posted this log from my computer so for now the internet hasn't caused my computer to crash which is good.

    Here is the other log.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Use windows explorer to locate and delete the below empty folders:
    Also delete this file if you do not know what it is:

    • C:\zrpt.xml

    Run Ccleaner.
    Now, are you having any other issues because those logs look good to me. I am not seeing any more malware.
     
  10. rove02

    rove02 Private E-2

    I deleted all the files listed above and as of now am not noticing any problems. Thank you so much for all your help. This forum is great, all the instructions were easy to follow and you were very quick to respond. I really appreciate all your help.

    At this point should I continue with the last few steps of the Cleaning Procedure?
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's great! :) You are *most* welcome for the help. Safe surfing!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  12. rove02

    rove02 Private E-2

    I did all of the above but when I went into Add/Remove Programs I did not see HijackThis in there so I was unable to remove it. Is this going to be an issue?
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Nope. It won't be an issue. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds